GHSA-7grf-83vw-6f5x
OpenZeppelin Contracts ERC165Checker unbounded gas consumption
Quick fix
GHSA-7grf-83vw-6f5x — @openzeppelin/contracts: upgrade to the fixed version with the command below.
npm install @openzeppelin/contracts@4.7.2Details
### Impact
The target contract of an EIP-165 `supportsInterface` query can cause unbounded gas consumption by returning a lot of data, while it is generally assumed that this operation has a bounded cost.
### Patches
The issue has been fixed in v4.7.2.
### References
https://github.com/OpenZeppelin/openzeppelin-contracts/pull/3587
### For more information
If you have any questions or comments about this advisory, or need assistance deploying a fix, email us at [security@openzeppelin.com](mailto:security@openzeppelin.com).
Are you affected?
Enter the version of the package you're using.
Affected packages
2.0.0Fixed in: 4.7.2npm install @openzeppelin/contracts@4.7.22.0.0No fixed version published yet for openzeppelin-solidity (npm). Pin to a known-safe version or switch to an alternative.
3.2.0Fixed in: 4.7.2npm install @openzeppelin/contracts-upgradeable@4.7.22.0.0No fixed version published yet for openzeppelin-eth (npm). Pin to a known-safe version or switch to an alternative.
References
- https://github.com/OpenZeppelin/openzeppelin-contracts/security/advisories/GHSA-7grf-83vw-6f5x[WEB]
- https://nvd.nist.gov/vuln/detail/CVE-2022-35915[ADVISORY]
- https://github.com/OpenZeppelin/openzeppelin-contracts/pull/3587[WEB]
- https://github.com/OpenZeppelin/openzeppelin-contracts[PACKAGE]
- https://github.com/OpenZeppelin/openzeppelin-contracts/releases/tag/v4.7.2[WEB]